Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.
Adobe has released isolated security patches for APSB26-92 for Adobe Commerce and Magento Open Source.
The update fixes seven vulnerabilities. Five are rated Critical, including CVE-2026-71362 , an unauthenticated customer account takeover with a CVSS score of 9.1. Exploitation needs no existing account, administrator privileges or user interaction.
Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data.
Adobe fixed the way Magento handles customer identity in the account session. The other vulnerabilities cover stored cross-site scripting and authorization flaws.
APSB26-92 does not come with a new security release or new Composer packages. Under Adobe's current patch schedule , monthly fixes are distributed as isolated patch files and later included in a full security patch.
Merchants must run the latest -p release for their supported release line before applying the corresponding isolated patch.
Running Sansec Shield ? You are already protected against this customer account takeover. Shield blocks attacks before they reach Magento, even when a security patch has not been installed yet.
Block all known Magento attacks, while you schedule the latest critical patch until a convenient moment. No more downtime and instability from rushed patching.
eComscan is the most thorough security scanner for Magento, Adobe Commerce, Shopware, WooCommerce, Sylius and many more.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
